Description
The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe way so that any javascript code inside the markdown input files gets evaluated and executed.
Remediation
References
https://snyk.io/vuln/SNYK-JS-POSTLOADER-2403737
Related Vulnerabilities
CVE-2021-32573 Vulnerability in npm package express-cart
CVE-2022-1243 Vulnerability in maven package org.webjars.bower:urijs
CVE-2021-21293 Vulnerability in maven package org.http4s:blaze-core_2.12
CVE-2020-7643 Vulnerability in npm package paypal-adaptive
CVE-2021-39134 Vulnerability in npm package @npmcli/arborist